Skip to content

INS-1676 CVE Fixes - #168

Merged
amattu2 merged 5 commits into
3.4.1from
INS-1676
Jun 24, 2026
Merged

INS-1676 CVE Fixes#168
amattu2 merged 5 commits into
3.4.1from
INS-1676

Conversation

@amattu2

@amattu2 amattu2 commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Overview

PR to patch both OS and Java CVEs.

Change Details (Specifics)

  • Bump Tomcat to 11.0.23
  • Bump Spring to 6.2.19
  • Bump Jackson to 2.18.8
  • Bump Netty to 4.1.135.Final

Related Ticket(s)

INS-1676 (Task)
INS-1662 (US)

@amattu2
amattu2 marked this pull request as ready for review June 24, 2026 17:20
Copilot AI review requested due to automatic review settings June 24, 2026 17:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates key runtime and framework dependencies (Tomcat, Spring Framework, Jackson, Netty) to address CVEs referenced by INS-1676/INS-1662, aligning both the build (Maven) and container runtime (Docker) artifacts.

Changes:

  • Bumped Spring Framework override to 6.2.19.
  • Updated Jackson BOM and Netty dependencies to newer patch releases.
  • Updated the production Docker base image to Tomcat 11.0.23 (JDK 17).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
pom.xml Updates Spring/Jackson/Netty/Tomcat dependency versions used for the application build.
Dockerfile Updates the runtime Tomcat base image tag to the patched version.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread pom.xml
@amattu2
amattu2 merged commit 0e8d426 into 3.4.1 Jun 24, 2026
1 check passed
@amattu2
amattu2 deleted the INS-1676 branch June 24, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants